Workshop: Digital Discovery with Bootable CDs

R. Moll, M. Prokop, H. Morgenstern
{"title":"Workshop: Digital Discovery with Bootable CDs","authors":"R. Moll, M. Prokop, H. Morgenstern","doi":"10.1109/IMF.2009.20","DOIUrl":null,"url":null,"abstract":"Boot-CDs are a flexible and powerful method to assist in the whole forensic process from live examination to acquisition, searching and recovery. Linux was ever since the most popular OS for this purpose, but in some cases windows-based Live-CDs are also useful. In this workshop we present different real-life case scenarios and the corresponding live-boot-solution. Since kernel 2.6 Linux is able to create forensically sound images even of partitions/harddisks with odd sectors. But one has to be aware of a lot of other circumstances which can alter the evidence: mounting filesystems, automatic activation of software RAID arrays, using LVMs or swap-space on the target disk. A lot of Linux-Boot-CDs seem to take care of all the critical points, but in fact there are only few well documented tests available. Another problem of the ready-to-download Linux Live-CD images is the lack of support for brand new hardware. So a framework to build a custom linux-live-system with current kernel versions and packages would be really helpful. We will present grml, a Debian based live system, developed by the Austrian Debian Developer Michael Prokop and the grml team. This system satisfies all the above mentioned initial conditions and much more. Various boot parameters allow to control the behavior of the live system, e.g. the parameter \"forensic\", which is a shortcut for \"nofstab noraid noautoconfig noswap raid=noautodetect readonly ...\". Additionally the grml system can be booted from CD/DVD, USB-/Firewire-Device, Remote-Adapter (iLO, RSA2, ...), Flash-Card and PXE. In this workshop you'll learn how to use grml for forensic investigations and how to build your own live system using the grml-live framework. On some brand-new mainboards the grml system might still fail, because the chipset, especially the onboard-raid-chipset is not yet supported by the linux kernel. For these cases a forensically sound windows-based boot-CD as plan B is needed. So the workshop will present a way to build a forensically sound windows based boot CD using the standard Windows Automated Installation Kit for Windows Vista along with some registry modifications.","PeriodicalId":370893,"journal":{"name":"2009 Fifth International Conference on IT Security Incident Management and IT Forensics","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2009-10-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2009 Fifth International Conference on IT Security Incident Management and IT Forensics","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IMF.2009.20","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Boot-CDs are a flexible and powerful method to assist in the whole forensic process from live examination to acquisition, searching and recovery. Linux was ever since the most popular OS for this purpose, but in some cases windows-based Live-CDs are also useful. In this workshop we present different real-life case scenarios and the corresponding live-boot-solution. Since kernel 2.6 Linux is able to create forensically sound images even of partitions/harddisks with odd sectors. But one has to be aware of a lot of other circumstances which can alter the evidence: mounting filesystems, automatic activation of software RAID arrays, using LVMs or swap-space on the target disk. A lot of Linux-Boot-CDs seem to take care of all the critical points, but in fact there are only few well documented tests available. Another problem of the ready-to-download Linux Live-CD images is the lack of support for brand new hardware. So a framework to build a custom linux-live-system with current kernel versions and packages would be really helpful. We will present grml, a Debian based live system, developed by the Austrian Debian Developer Michael Prokop and the grml team. This system satisfies all the above mentioned initial conditions and much more. Various boot parameters allow to control the behavior of the live system, e.g. the parameter "forensic", which is a shortcut for "nofstab noraid noautoconfig noswap raid=noautodetect readonly ...". Additionally the grml system can be booted from CD/DVD, USB-/Firewire-Device, Remote-Adapter (iLO, RSA2, ...), Flash-Card and PXE. In this workshop you'll learn how to use grml for forensic investigations and how to build your own live system using the grml-live framework. On some brand-new mainboards the grml system might still fail, because the chipset, especially the onboard-raid-chipset is not yet supported by the linux kernel. For these cases a forensically sound windows-based boot-CD as plan B is needed. So the workshop will present a way to build a forensically sound windows based boot CD using the standard Windows Automated Installation Kit for Windows Vista along with some registry modifications.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
研讨会:数字发现与可启动cd
引导光盘是一种灵活而强大的方法,可以协助从现场检查到获取,搜索和恢复的整个法医过程。从那以后,Linux一直是最受欢迎的操作系统,但在某些情况下,基于windows的live - cd也很有用。在本次研讨会中,我们将介绍不同的实际案例场景和相应的实时启动解决方案。自2.6内核以来,Linux甚至能够创建具有奇数扇区的分区/硬盘的可靠映像。但是必须意识到许多其他可能改变证据的情况:挂载文件系统、自动激活软件RAID阵列、在目标磁盘上使用lvm或交换空间。许多linux - boot - cd似乎处理了所有的关键点,但实际上只有很少有文档完备的可用测试。随时可下载的Linux Live-CD映像的另一个问题是缺乏对全新硬件的支持。因此,使用当前内核版本和软件包构建自定义linux实时系统的框架将非常有帮助。我们将介绍grml,一个基于Debian的实时系统,由奥地利Debian开发人员Michael Prokop和grml团队开发。该系统满足上述所有初始条件,甚至更多。各种引导参数允许控制活动系统的行为,例如参数“forensic”,这是“nofstab noraid noautoconfig noswap raid=noautodetect readonly…”的快捷方式。此外,grml系统可以从CD/DVD, USB-/火线设备,远程适配器(iLO, RSA2,…),闪存卡和PXE启动。在本研讨会中,您将学习如何使用grml进行取证调查,以及如何使用grml-live框架构建自己的实时系统。在一些全新的主板上,grml系统可能仍然会失败,因为linux内核还不支持芯片组,特别是板载raid芯片组。对于这些情况,需要一个可靠的基于windows的启动cd作为B计划。因此,研讨会将介绍一种方法来建立一个法医健全的基于windows的启动CD使用标准的windows自动安装套件的windows Vista以及一些注册表修改。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Workshop: Digital Discovery with Bootable CDs Self-Forensics Through Case Studies of Small-to-Medium Software Systems Technique to Interrogate an Image of RAM Fast User Classifying to Establish Forensic Analysis Priorities Safe-Keeping Digital Evidence with Secure Logging Protocols: State of the Art and Challenges
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1